A customer you worked with three years ago sends you an email. They need a reference, or a copy of something you did for them back then. You still have their file, so you can help.
But open that file and look at what's actually inside. Their NRIC. A home address they've probably moved out of. Bank details from a payment they made once. Everything you collected at the start, still sitting there, long after the reason you collected it has passed.
You kept the file to be helpful. That part is fine.
The problem is everything else you kept along with it.
Keeping data is not the same as needing all of it
Part of my job as a DPO is helping clients make sure they are not holding personal data longer than they need. The idea is simple enough. Data should be kept only for as long as it is still necessary for the purpose it was collected for. Once that purpose is gone, and there is no legal or business reason to hold on, you are expected to stop.
Most people read that as one instruction. When you no longer need it, delete it.
In practice, it is rarely that clean.
I was reviewing data retention with a client recently. On paper the answer looked easy. Old records, purpose served, time to delete. But it wasn't that easy. Their former users come back. Months, sometimes years later, someone asks for a reference or a confirmation of what they did together. To provide that, the client genuinely needs to keep a record.
So deletion was off the table. The reason to retain was real.
But that did not mean they had to keep everything.
The second lever most businesses forget
When people think about retention, they think about time. How long do we keep this.
There is a second lever, and it is the one most businesses forget. Not how long you keep the data, but how much of it.
The client needed enough to confirm a past relationship and provide a reference. They did not need the NRIC. They did not need the old bank details, or the sensitive personal data collected for a purpose that had ended long ago.
So that is what we did. We kept the record, and we removed the sensitive personal data that no longer served any purpose. The file still does its job. It just carries far less risk.
The law supports exactly this line of thinking. The PDPA's Retention Limitation Obligation says that once the purpose is served and there is no legal or business need, an organisation should stop retaining the data, either by deleting it or by removing the means to identify anyone from it. My client had a genuine business reason to keep an identifiable record, so neither full deletion nor full anonymisation fit their case. But the principle underneath the obligation still applies. Hold only what you actually need. That is data minimisation, and it is good practice whether or not the law forces your hand.
Why this matters more than it sounds
Here is the part that makes it worth the effort.
Every piece of personal data you hold is something you have to protect. It is also something that can be lost if you are breached.
You cannot lose what you no longer hold.
If that client is breached next year, the NRIC and bank details we removed are not in the exposure. They are gone. The damage is smaller because the target is smaller. Minimising the data you keep is one of the quietest, most effective ways to reduce the cost of a breach, and it costs you almost nothing to do now.
The reason it doesn't happen is not that people don't care. It's that nobody owns the question. The data was collected, the work got done, and the file just stayed. Nobody comes back to ask whether every field in it still needs to be there.
What to do next
You don't need a project for this. You need to ask a few questions about the data you are already sitting on.
For each store of old records, ask:
- Why are we still keeping this? Is there a real business or legal reason, or is it just there?
- If we do need to keep it, do we need all of it, or only part of it?
- Which fields are sensitive, and could those be removed while keeping the record useful?
- What would actually be exposed if this store were breached tomorrow?
The goal is not to delete for the sake of it. The goal is to hold the least you can while still doing what you need to do.
Keeping the record is not the risk. Keeping everything is.
If you are not sure what your business is still holding, or who owns that question, it is the kind of thing a proper retention review is meant to surface. That is part of the work we do at Veritos, helping organisations stay clear on what they hold, why, and for how long.
